feat: server-side OAuth token management system
Co-Authored-By: Classic298 <27028174+Classic298@users.noreply.github.com>
This commit is contained in:
co-authored by
Classic298
parent
6d38ac41b6
commit
217f4daef0
@@ -19,6 +19,7 @@ from open_webui.models.auths import (
|
||||
)
|
||||
from open_webui.models.users import Users, UpdateProfileForm
|
||||
from open_webui.models.groups import Groups
|
||||
from open_webui.models.oauth_sessions import OAuthSessions
|
||||
|
||||
from open_webui.constants import ERROR_MESSAGES, WEBHOOK_MESSAGES
|
||||
from open_webui.env import (
|
||||
@@ -28,7 +29,6 @@ from open_webui.env import (
|
||||
WEBUI_AUTH_TRUSTED_GROUPS_HEADER,
|
||||
WEBUI_AUTH_COOKIE_SAME_SITE,
|
||||
WEBUI_AUTH_COOKIE_SECURE,
|
||||
ENABLE_OAUTH_SESSION_TOKENS_COOKIES,
|
||||
WEBUI_AUTH_SIGNOUT_REDIRECT_URL,
|
||||
ENABLE_INITIAL_ADMIN_SIGNUP,
|
||||
SRC_LOG_LEVELS,
|
||||
@@ -678,24 +678,27 @@ async def signout(request: Request, response: Response):
|
||||
response.delete_cookie("token")
|
||||
response.delete_cookie("oui-session")
|
||||
|
||||
if ENABLE_OAUTH_SIGNUP.value:
|
||||
# TODO: update this to use oauth_session_tokens in User Object
|
||||
oauth_id_token = request.cookies.get("oauth_id_token")
|
||||
oauth_session_id = request.cookies.get("oauth_session_id")
|
||||
if oauth_session_id:
|
||||
response.delete_cookie("oauth_session_id")
|
||||
|
||||
if oauth_id_token and OPENID_PROVIDER_URL.value:
|
||||
session = OAuthSessions.get_session_by_id(oauth_session_id)
|
||||
oauth_server_metadata_url = (
|
||||
request.app.state.oauth_manager.get_server_metadata_url(session.provider)
|
||||
if session
|
||||
else None
|
||||
) or OPENID_PROVIDER_URL.value
|
||||
|
||||
if session and oauth_server_metadata_url:
|
||||
oauth_id_token = session.token.get("id_token")
|
||||
try:
|
||||
async with ClientSession(trust_env=True) as session:
|
||||
async with session.get(OPENID_PROVIDER_URL.value) as r:
|
||||
async with session.get(oauth_server_metadata_url) as r:
|
||||
if r.status == 200:
|
||||
openid_data = await r.json()
|
||||
logout_url = openid_data.get("end_session_endpoint")
|
||||
|
||||
if logout_url:
|
||||
if ENABLE_OAUTH_SESSION_TOKENS_COOKIES:
|
||||
response.delete_cookie("oauth_id_token")
|
||||
response.delete_cookie("oauth_access_token")
|
||||
response.delete_cookie("oauth_refresh_token")
|
||||
|
||||
return JSONResponse(
|
||||
status_code=200,
|
||||
content={
|
||||
@@ -710,15 +713,14 @@ async def signout(request: Request, response: Response):
|
||||
headers=response.headers,
|
||||
)
|
||||
else:
|
||||
raise HTTPException(
|
||||
status_code=r.status,
|
||||
detail="Failed to fetch OpenID configuration",
|
||||
)
|
||||
raise Exception("Failed to fetch OpenID configuration")
|
||||
|
||||
except Exception as e:
|
||||
log.error(f"OpenID signout error: {str(e)}")
|
||||
raise HTTPException(
|
||||
status_code=500,
|
||||
detail="Failed to sign out from the OpenID provider.",
|
||||
headers=response.headers,
|
||||
)
|
||||
|
||||
if WEBUI_AUTH_SIGNOUT_REDIRECT_URL:
|
||||
|
||||
Reference in New Issue
Block a user